Threat Brief — 2026-09-04 — Old bugs, new lawsuits, passkeys under fire
A 12-year-old PostgreSQL replication flaw enabling OS-level code execution heads today's list, alongside CISA's KEV catalog addition for the actively exploited Chrome V8 zero-day. IDScan now faces multiple lawsuits over the alleged breach of 153 million driver's licenses, and researchers have documented 39 distinct methods for compromising passkey-based authentication — a timely reminder that passwordless does not mean attack-free.
Top items
- PostgreSQL patches 12-year-old logical decoding flaw (CVE-2026-6471). An account with the REPLICATION attribute can exploit the vulnerability to execute arbitrary code as the OS user running the database server. The flaw has existed for over a decade, meaning any long-running PostgreSQL deployment that granted REPLICATION to semi-trusted accounts is potentially exposed. Updates are now available. (src: The Hacker News)
- CISA adds Chrome V8 zero-day CVE-2026-85046KEV to Known Exploited Vulnerabilities catalog. This is a genuine development in the ongoing Chrome V8 type-confusion story, first reported earlier today by The Hacker News. CISA's KEV addition confirms active in-the-wild exploitation and imposes federal remediation deadlines. The vulnerability allows type confusion in the V8 JavaScript engine, potentially enabling remote code execution through a malicious web page. (src: CISA Current Activity) — first reported 2026-09-04 by The Hacker News
- Pyramid Solutions NetStaX EtherNet/IP Stack advisory issued. CISA published an ICS advisory for a vulnerability in the NetStaX EtherNet/IP stack that could result in memory corruption, device crash, or a remote attack vector without the originating device receiving a CIP error response — meaning failed exploit attempts may go undetected by standard monitoring. (src: CISA ICS Advisory)
- IDScan faces multiple lawsuits over alleged breach of 153 million driver's licenses. This is a development in the ongoing story first reported 2026-09-01 by Krebs on Security. Multiple lawsuits have now been filed against the identity verification company after hackers allegedly breached the service and offered to sell more than 153 million driver's license records. (src: BleepingComputer) — first reported 2026-09-01 by Krebs on Security
- Researchers document 39 methods for compromising passkey authentication. While passkeys eliminate most password-based attacks, a new analysis outlines 39 distinct attack vectors targeting authentication prompts, synced credentials, enrollment processes, and recovery flows. The findings suggest that passkey deployments require the same defensive scrutiny as legacy authentication. (src: BleepingComputer)
- Report warns organizations have roughly six months to prepare for autonomous AI-driven attacks. Frontier AI models have already demonstrated end-to-end compromise capabilities in controlled settings; the analysis argues the window before these capabilities are routinely weaponized in the wild is narrowing rapidly. (src: Dark Reading)
Themes
Legacy code surfaces again. Both the PostgreSQL flaw (12 years old) and the Pyramid Solutions EtherNet/IP advisory illustrate that long-embedded code paths remain a fertile attack surface — particularly when privileged roles or industrial protocols are involved. Organisations granting REPLICATION-level access or running ICS stacks should treat these as priority review items.
Passwordless ≠ risk-free. The passkey compromise research lands at a moment when major platforms are aggressively pushing passkey adoption. The 39 documented methods span the full authentication lifecycle, not just the cryptographic core, underscoring that identity-infrastructure decisions matter as much as the underlying primitive.
